Agent skill

Harden

by athola in athola/claude-night-market

Applies NIST/CWE security hardening to Python and Rust code.

MITAuto-check passedSecurity

Install Harden

skills CLI
$ npx skills add athola/claude-night-market --skill harden -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market harden --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pensive/skills/harden .claude/skills/harden && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
harden
GitHub stars
341
Token cost
~2.7k tokens
SKILL.md length
936 words
Files
7
Skills in repo
152
Repo updated
First seen
Licence
MIT

At a glance

Applies NIST/CWE security hardening to Python and Rust code.

  • Works in 7 steps: Discovery → Citation-backed scan → NIST mapping → …
  • Auditing code for vulnerabilities
  • SKILL.md covers When To Use, When NOT To Use, Required TodoWrite Items and Progressive Loading, plus 6 more sections
  • Calls git and make

What it does

Harden is an agent skill from athola/claude-night-market. Applies NIST/CWE security hardening to Python and Rust code. Use when auditing code for vulnerabilities or proposing concrete security remediations.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `modules/cross-cutting.md`, `modules/frontier-checks.md` and `modules/nist-controls.md`).

It sits in Security, covering Security review. It works with Python and Rust. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Auditing code for vulnerabilities
  • Proposing concrete security remediations

Example prompts

  • “Use the harden skill to apply NIST/CWE security hardening to Python and Rust code”
  • “/harden”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Discovery
  2. Citation-backed scan
  3. NIST mapping
  4. Proposal generation
  5. Approval gate
  6. Apply and validate
  7. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Harden loads about 2.7k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 936 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 936 words, ~2,684 tokens.

Download SKILL.mdSave it as .claude/skills/harden/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
harden
description
Applies NIST/CWE security hardening to Python and Rust code. Use when auditing code for vulnerabilities or proposing concrete security remediations.
globs
**/*.{py,rs,toml,yaml,yml,sh}
alwaysApply
false
category
security
tags
security, hardening, nist, supply-chain, python, rust, cwe
provides.governance
hardening-report, remediation-proposal
provides.security
vuln-detection, hardening-posture
usage_patterns
security-hardening, quarterly-posture-audit, pre-release-security-gate
complexity
advanced
model_hint
deep
estimated_tokens
1100

Harden Codebase Skill

Active security hardening: scan the existing repository for vulnerabilities and forward-facing threats, then propose concrete remediations the user can approve, defer, or file.

This skill is the engine behind /harden. It complements the Claude Code built-in /security-review (which scans the pending diff) by sweeping the whole repository against citation-backed checks rather than line-level review of in-flight code.

When To Use

  • Quarterly security-posture audits.
  • Before tagging a release that touches sensitive code paths.
  • After a published advisory affects the language ecosystem.
  • When onboarding a new repository and want a baseline.
  • After integrating a new dependency or upstream service.

When NOT To Use

  • Pending-diff review on a single PR. Use /security-review.
  • Architecture-level threat modeling. Use attune:war-room with a security-focused panel.
  • Cryptographic protocol review. The skill flags suspect crypto but does not propose protocol fixes (specialist work).
  • One-off bug hunting. Use pensive:bug-review.

Required TodoWrite Items

  1. harden:discovery: inventory languages, build files, hooks, CI workflows
  2. harden:scan-python: run python-checks.md detectors when Python is present
  3. harden:scan-rust: run rust-checks.md detectors when Rust is present
  4. harden:scan-cross-cutting: run cross-cutting.md detectors (deps, secrets, SBOM, CI)
  5. harden:scan-frontier: run frontier-checks.md (PQC, LLM supply chain, sandboxing)
  6. harden:nist-mapping: map findings to NIST SSDF practices
  7. harden:proposals: for each finding above the threshold, draft a concrete remediation per modules/proposal-shape.md
  8. harden:approval-gate: present proposals to the user for apply / file / defer / reject
  9. harden:apply-and-validate: apply approved proposals as discrete commits, re-run gates, capture evidence
  10. harden:findings-verified: citations confirmed by citation_verifier.py
  11. harden:report: write reviews/harden-<date>.md and optionally post to Discussions

Progressive Loading

Load modules based on what the discovery step finds.

DetectedLoad
Python files (*.py, pyproject.toml)modules/python-checks.md
Rust files (*.rs, Cargo.toml)modules/rust-checks.md
Anymodules/nist-controls.md (citation backbone)
Anymodules/cross-cutting.md (deps, secrets, CI)
LLM SDK use (anthropic, openai), MCP server, post-quantum surfacemodules/frontier-checks.md
Any with proposals enabledmodules/proposal-shape.md

The module hub keeps the SKILL.md itself under the estimated_tokens: 1100 budget. Detail lives in the modules.

Core Workflow

Phase 1: Discovery

Inventory the repo without modifying anything:

bash
# Languages and build files
find . -type f \( -name '*.py' -o -name '*.rs' -o -name '*.sh' \) \
  | head -200 > /tmp/harden-langs.txt

# Build manifests
ls pyproject.toml Cargo.toml package.json go.mod 2>/dev/null

# CI workflows and pre-commit
ls .github/workflows/ .pre-commit-config.yaml 2>/dev/null

# Hooks and Dockerfiles
find . -path ./node_modules -prune -o -type f \
  \( -name 'hooks.json' -o -name 'Dockerfile*' \) -print

Dispatch /discovery-prefilter if the repo has > 5000 source files to bound the scan.

Phase 2: Citation-backed scan

For each detected language, load the matching module and run its detector list. Each detector outputs findings with the schema defined in modules/proposal-shape.md. The citation column is mandatory: a finding without a NIST/CWE reference is downgraded to "advisory" and not eligible for active proposal.

Phase 3: NIST mapping

Group findings by SSDF practice (PW.4, PW.8, RV.1, etc.) and CWE ID. The mapping table lives in modules/nist-controls.md. The report's executive summary references SSDF practice coverage so the audit is comparable across runs.

Phase 4: Proposal generation

For each finding above the configured severity threshold, draft a concrete remediation per modules/proposal-shape.md:

  • Specific files and lines touched
  • Diff or config snippet (not "consider doing X")
  • Blast-radius assessment via pensive:blast-radius
  • Reversal plan: how to revert if the change breaks behavior
  • Test that should pass after the change
Phase 5: Approval gate

Present proposals one at a time via AskUserQuestion. Default options: apply, file as issue, defer to backlog, reject. Auto-apply is opt-in via the --auto-apply flag and respects a per-finding severity threshold.

Phase 6: Apply and validate

Apply each approved proposal as a discrete commit:

bash
git add <touched files>
git commit -m "harden: <finding-id> <one-line summary>"

After each apply, re-run the project gates:

bash
make test --quiet && make lint && make type-check

If a gate fails, revert the commit (git revert HEAD --no-edit) and downgrade the finding to "needs human design."

Show full SKILL.md (386 more words)Show less
Phase 7: Report

Write reviews/harden-<date>.md with:

  • Executive summary (SSDF practice coverage, CWE distribution)
  • Findings table grouped by severity
  • Per-finding detail: detection signal, citation, proposal, status
  • Disposition table (applied / filed / deferred / rejected)
  • Re-run instructions

If running inside a PR context, post the executive summary as a comment via abstract:post_review_insights.

Severity Classification

SeverityDefinitionDefault disposition
CRITICALActive exploit path, RCE, credential leakapply or file immediately
HIGHPlausible exploit, missing defense-in-depth on attack surfacepropose for apply
MEDIUMBest-practice gap, hardening opportunitypropose for apply with --auto-apply medium
LOWStyle/documentation gap with security flavorfile as issue
ADVISORYPattern detected without exploit narrativereport only

Output Format

markdown
# Hardening Report — <date>

## Executive Summary

- Codebase: <repo> @ <sha>
- Languages scanned: Python (X files), Rust (Y files)
- NIST SSDF practices covered: PW.4, PW.7, PW.8, RV.1, RV.2
- CWE Top 25 hits: <count> across <distinct CWEs>
- Disposition: <N> applied, <N> filed, <N> deferred, <N> rejected

## Findings

| ID | Severity | Citation | File:Line | Disposition |
|----|----------|----------|-----------|-------------|
| H1 | CRITICAL | CWE-502, NIST SSDF PW.7 | `src/x.py:45` | applied (commit abc123) |
| H2 | HIGH | CWE-89, NIST SSDF PW.4 | `src/y.py:120` | filed (#456) |

## Per-finding detail

### H1 — Unsafe deserialization

**Citation:** CWE-502 (Deserialization of Untrusted Data),
NIST SSDF PW.7 (Review and analyze human-readable code).

**Detection signal:**
- File: `src/x.py:45`
- Anchor: `data = pickle.loads(user_supplied_input)`
- Pattern: <module>.loads(user_supplied_input)
- Reachability: untrusted, comes from request body

**Proposal:** ...

**Blast radius:** ...

**Reversal plan:** ...

Safety Rails

  • Never apply without approval. Even with --auto-apply, CRITICAL findings always prompt.
  • One finding per commit. Reversals are per-finding, not per-batch.
  • Re-run gates after each apply. A gate failure reverts the commit and downgrades the finding.
  • Citation is mandatory. Findings without a NIST/CWE/RustSec reference are advisory only and skip the apply phase.
  • Read-only on first run. First invocation defaults to --report-only until the user has reviewed at least one report and explicitly opts into proposals.

Integration

The skill composes (rather than re-implements):

  • pensive:rust-review: full Rust audit when Rust is present
  • pensive:bug-review: bug-hunting backbone
  • pensive:safety-critical-patterns: NASA Power-of-10 adapted
  • pensive:tiered-audit: three-tier discipline (--tier 1/2/3)
  • pensive:blast-radius: change-impact assessment for proposals
  • leyline:supply-chain-advisory: dependency posture
  • leyline:authentication-patterns: auth/credential review
  • leyline:content-sanitization: input handling
  • abstract:hook-authoring: hook-event security
  • imbue:proof-of-work: evidence discipline for findings
Verify Findings Are Grounded (harden:findings-verified)

Write findings to .review/findings.json, run the citation verifier (Skill(imbue:review-core) Step 5), and drop or label UNVERIFIED any the verifier rejects.

Exit Criteria

  • Discovery output lists every language and build manifest detected in the repo.
  • Each finding carries a CWE or NIST SSDF citation; the report executive summary lists the SSDF practice coverage.
  • Each finding above the severity threshold has a concrete proposal (file, diff or config snippet, blast radius, reversal plan, expected-passing test).
  • No proposal was applied without explicit user approval (or without an --auto-apply flag covering its severity).
  • Each applied proposal is its own commit, reversal-friendly.
  • After every apply, the project gates were re-run; any gate failure reverted the commit and downgraded the finding.
  • reviews/harden-<date>.md exists and lists every finding with a disposition (applied / filed / deferred / rejected / advisory).
  • Every reported finding carries a Location + verbatim Anchor confirmed by citation_verifier.py (exit 0), or unverified findings were dropped or labeled UNVERIFIED.

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in plugins/pensive/skills/harden of athola/claude-night-market.

  • SKILL.md
  • modules/cross-cutting.md
  • modules/frontier-checks.md
  • modules/nist-controls.md
  • modules/proposal-shape.md
  • modules/python-checks.md
  • modules/rust-checks.md

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Harden next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Harden compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Harden this skillathola/claude-night-market341—~2.7kAutomated safety check: PassMIT
Review Securitypydantic/monty8.6k—~852Automated safety check: PassMIT
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Security AuditTheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Common Security AuditHoangNguyen0403/agent-skills-standard572—~977Automated safety check: PassMIT

Similar skills

  • Review Security

    pydantic/monty

    Official

    Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

    8.6k GitHub stars~852 tokensUpdated today
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 3 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Common Security Audit

    HoangNguyen0403/agent-skills-standard

    Probe for hardcoded secrets, injection surfaces, unguarded routes, business logic flaws, and platform-specific weaknesses across backend (Node, Go, Java, Python, Rust), frontend (React, Angular…

    572 GitHub stars~977 tokensUpdated today
    SecurityAuto-check passed
  • Code Review Excellence

    andrew-yangy/gru-ai

    Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.

    155 GitHub stars~1.7k tokensUpdated 7 mo ago
    DevelopmentAuto-check: notes

More from athola/claude-night-market

All 152 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    341 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    341 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    341 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    341 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    341 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    341 GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Harden

What does Harden do?

Applies NIST/CWE security hardening to Python and Rust code. Harden is an agent skill from athola/claude-night-market. Applies NIST/CWE security hardening to Python and Rust code.

When should I use Harden?

Harden fits situations like: auditing code for vulnerabilities; proposing concrete security remediations.

How do I install Harden in Claude Code?

Run `npx skills add athola/claude-night-market --skill harden -a claude-code`. Or copy the skill folder (plugins/pensive/skills/harden in athola/claude-night-market) into .claude/skills/harden in your project. Claude Code loads it when a task matches its description.

How do I install Harden in Codex?

Run `npx skills add athola/claude-night-market --skill harden -a codex`. Or copy the skill folder (plugins/pensive/skills/harden in athola/claude-night-market) into .agents/skills/harden in your project. Codex loads it when a task matches its description.

Can I use Harden in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill harden -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harden, .gemini/skills/harden, .github/skills/harden and .opencode/skills/harden in your project.

What does Harden need to run?

Going by SKILL.md and its folder, Harden needs the command-line tools its instructions call (git and make). Our summary lists: Python 3.

Does Harden access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Harden safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Harden use?

Harden is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Harden use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Harden?

Skills that share tags, products or a category with Harden: Review Security (pydantic/monty, 8.6k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Harden?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on October 9, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.